{"cves":[{"id":"CVE-2014-7283","published":"2014-10-13T00:00:00","updated_at":"2026-07-04T07:39:58.897995+00:00","description":"\nThe xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs\nimplementation in the Linux kernel before 3.14.2 does not properly compare\nbtree hash values, which allows local users to cause a denial of service\n(filesystem corruption, and OOPS or panic) via operations on directories\nthat have hash collisions, as demonstrated by rmdir operations.","ubuntu_description":"\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.04 preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support\nper Debian, introduced in 3.10\nreproducer: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=xfs/cmds/xfstests.git;a=commitdiff;h=947ee8bd4b59770534297572b14c695e9c6e001e\nper apw, this was fixed in passing in 3.13.0-39.66~precise1, part of\nhttps://ubuntu.com/security/notices/USN-2394-1, but not documented in the changelog or\nthe USN."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=linux-xfs&m=139590613002926&w=2","https://ubuntu.com/security/notices/USN-2226-1","https://ubuntu.com/security/notices/USN-2239-1","https://ubuntu.com/security/notices/USN-2394-1","https://ubuntu.com/security/notices/USN-2260-1","https://www.cve.org/CVERecord?id=CVE-2014-7283"],"bugs":["https://launchpad.net/bugs/1377337"],"patches":{"linux":["break-fix: f5ea110044fa858925a880b4fa9f551bfa2dfc38 c88547a8119e3b581318ab65e9b72f27f23e641d"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-raspi2":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-27.50","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.15.0-1.5","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.11.0-23.40~precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.13.0-27.50~precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2226-1","USN-2260-1","USN-2239-1"],"notices":[{"id":"USN-2226-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-05-27T06:49:10.556919","description":"\nMatthew Daley reported an information leak in the floppy disk driver of the\nLinux kernel. An unprivileged local user could exploit this flaw to obtain\npotentially sensitive information from kernel memory. (CVE-2014-1738)\n\nMatthew Daley reported a flaw in the handling of ioctl commands by the\nfloppy disk driver in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges if the floppy disk\nmodule is loaded. (CVE-2014-1737)\n\nA flaw was discovered in the handling of network packets when mergeable\nbuffers are disabled for virtual machines in the Linux kernel. Guest OS\nusers may exploit this flaw to cause a denial of service (host OS crash) or\npossibly gain privilege on the host OS. (CVE-2014-0077)\n\nTörök Edwin discovered a flaw with Xen netback driver when used with\nLinux configurations that do not allow sleeping in softirq context. A guest\nadministrator could exploit this flaw to cause a denial of service (system\ncrash) on the host. (CVE-2014-2580)\n\nA flaw was discovered in the Linux kernel's ping sockets. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\ncrash) or possibly gain privileges via a crafted application.\n(CVE-2014-2851)\n\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).\n(CVE-2014-7283)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-27.50","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-27-generic","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-generic-lpae","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-lowlatency","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-e500","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-e500mc","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-smp","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc64-emb","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc64-smp","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-extra-3.13.0-27-generic","version":"3.13.0-27.50","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0077","CVE-2014-1737","CVE-2014-1738","CVE-2014-2580","CVE-2014-2851","CVE-2014-7283"]},{"id":"USN-2260-1","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-06-27T08:47:01.477060","description":"\nA flaw was discovered in the Linux kernel's pseudo tty (pty) device. An\nunprivileged user could exploit this flaw to cause a denial of service\n(system crash) or potentially gain administrator privileges.\n(CVE-2014-0196)\n\nPinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (system crash) or gain administrative privileges. (CVE-2014-3153)\n\nMatthew Daley reported an information leak in the floppy disk driver of the\nLinux kernel. An unprivileged local user could exploit this flaw to obtain\npotentially sensitive information from kernel memory. (CVE-2014-1738)\n\nMatthew Daley reported a flaw in the handling of ioctl commands by the\nfloppy disk driver in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges if the floppy disk\nmodule is loaded. (CVE-2014-1737)\n\nA flaw was discovered in the handling of network packets when mergeable\nbuffers are disabled for virtual machines in the Linux kernel. Guest OS\nusers may exploit this flaw to cause a denial of service (host OS crash) or\npossibly gain privilege on the host OS. (CVE-2014-0077)\n\nAn information leak was discovered in the netfilter subsystem of the Linux\nkernel. An attacker could exploit this flaw to obtain sensitive information\nfrom kernel memory. (CVE-2014-2568)\n\nTörök Edwin discovered a flaw with Xen netback driver when used with\nLinux configurations that do not allow sleeping in softirq context. A guest\nadministrator could exploit this flaw to cause a denial of service (system\ncrash) on the host. (CVE-2014-2580)\n\nA flaw was discovered in the Linux kernel's ping sockets. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\ncrash) or possibly gain privileges via a crafted application.\n(CVE-2014-2851)\n\nSasha Levin reported a bug in the Linux kernel's virtual memory management\nsubsystem. An unprivileged local user could exploit this flaw to cause a\ndenial of service (system crash). (CVE-2014-3122)\n\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).\n(CVE-2014-7283)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-30.54~precise2","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-3.13.0-30-generic","version":"3.13.0-30.54~precise2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-30.54~precise2"},{"name":"linux-image-3.13.0-30-generic-lpae","version":"3.13.0-30.54~precise2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-30.54~precise2"}]},"type":"USN","cves_ids":["CVE-2014-0077","CVE-2014-0196","CVE-2014-1737","CVE-2014-1738","CVE-2014-2568","CVE-2014-2580","CVE-2014-2851","CVE-2014-3122","CVE-2014-3153","CVE-2014-7283"]},{"id":"USN-2239-1","title":"Linux kernel (Saucy HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-06-05T21:50:42.581222","description":"\nPinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (system crash) or gain administrative privileges. (CVE-2014-3153)\n\nA flaw was discovered in the Linux kernel virtual machine's (kvm)\nvalidation of interrupt requests (irq). A guest OS user could exploit this\nflaw to cause a denial of service (host OS crash). (CVE-2014-0155)\n\nAn information leak was discovered in the netfilter subsystem of the Linux\nkernel. An attacker could exploit this flaw to obtain sensitive information\nfrom kernel memory. (CVE-2014-2568)\n\nSasha Levin reported a bug in the Linux kernel's virtual memory management\nsubsystem. An unprivileged local user could exploit this flaw to cause a\ndenial of service (system crash). (CVE-2014-3122)\n\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).\n(CVE-2014-7283)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-saucy","version":"3.11.0-23.40~precise1","description":"Linux hardware enablement kernel from Saucy","is_source":true},{"name":"linux-image-3.11.0-23-generic","version":"3.11.0-23.40~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-23.40~precise1"},{"name":"linux-image-3.11.0-23-generic-lpae","version":"3.11.0-23.40~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-23.40~precise1"}]},"type":"USN","cves_ids":["CVE-2014-0155","CVE-2014-2568","CVE-2014-3122","CVE-2014-3153","CVE-2014-7283"]}]},{"id":"CVE-2014-4737","published":"2014-10-10T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7\nallows remote attackers to inject arbitrary web script or HTML via the\nPATH_INFO to setup/index.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.htbridge.com/advisory/HTB23223","http://xforce.iss.net/xforce/xfdb/96802","http://textpattern.com/weblog/379/textpattern-cms-457-released-ten-years-on","http://packetstormsecurity.com/files/128519/Textpattern-4.5.5-Cross-Site-Scripting.html","https://www.cve.org/CVERecord?id=CVE-2014-4737"],"bugs":[""],"patches":{"textpattern":[]},"tags":{},"packages":[{"name":"textpattern","source":"https://ubuntu.com/security/cve?package=textpattern","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=textpattern","debian":"https://tracker.debian.org/pkg/textpattern","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-6439","published":"2014-10-10T01:55:00","updated_at":"2025-10-29T21:05:40.049603+00:00","description":"\nCross-site scripting (XSS) vulnerability in the CORS functionality in\nElasticsearch before 1.4.0.Beta1 allows remote attackers to inject\narbitrary web script or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-6439"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763958"],"patches":{"elasticsearch":[]},"tags":{},"packages":[{"name":"elasticsearch","source":"https://ubuntu.com/security/cve?package=elasticsearch","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elasticsearch","debian":"https://tracker.debian.org/pkg/elasticsearch","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.3+dfsg-4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3201","published":"2014-10-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncore/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in\nGoogle Chrome before 38.0.2125.102 on Android, does not properly handle a\ncertain IFRAME overflow condition, which allows remote attackers to spoof\ncontent via a crafted web site that interferes with the scrollbar.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Our packages include the RenderLayerCompositor.cpp file; I assume\nthis affects us, too, despite the \"on Android\" mention."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=182021&view=revision","https://crbug.com/406593","http://googlechromereleases.blogspot.com/2014/10/chrome-for-android-update.html","https://www.cve.org/CVERecord?id=CVE-2014-3201"],"bugs":[""],"patches":{"chromium-browser":["upstream: https://src.chromium.org/viewvc/blink?revision=182021&view=revision"],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"38.0.2125.111-0ubuntu0.14.04.1.1061","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0.2125.102","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"38.0.2125.111-0ubuntu0.14.10.1.1103","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4488","published":"2014-10-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibgadu before 1.12.0 does not verify X.509 certificates from SSL servers,\nwhich allows man-in-the-middle attackers to spoof servers.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"we build with the gnutls backend\nupstream certs don't actually match host names used, so\ncorrect cert validation is difficult."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/10/31","http://www.mail-archive.com/libgadu-devel@lists.ziew.org/msg01017.html","https://www.cve.org/CVERecord?id=CVE-2013-4488"],"bugs":["https://bugzilla.novell.com/show_bug.cgi?id=848653","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4488"],"patches":{"libgadu":[]},"tags":{},"packages":[{"name":"libgadu","source":"https://ubuntu.com/security/cve?package=libgadu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgadu","debian":"https://tracker.debian.org/pkg/libgadu","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3581","published":"2014-10-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cache_merge_headers_out function in modules/cache/cache_util.c in the\nmod_cache module in the Apache HTTP Server before 2.4.11 allows remote\nattackers to cause a denial of service (NULL pointer dereference and\napplication crash) via an empty HTTP Content-Type header.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"per upstream bug, 2.2 is not affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2523-1","https://www.cve.org/CVERecord?id=CVE-2014-3581"],"bugs":["https://issues.apache.org/bugzilla/show_bug.cgi?id=56924"],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1624234","upstream: https://github.com/apache/httpd/commit/c164ca7383d5f204915d85a5826655d3f1557148"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"2.2.14-5ubuntu8.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.2.22-1ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.10-3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.4.10-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2523-1"],"notices":[{"id":"USN-2523-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in the Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T14:49:16.270819","description":"Martin Holst Swende discovered that the mod_headers module allowed HTTP\ntrailers to replace HTTP headers during request processing. A remote\nattacker could possibly use this issue to bypass RequestHeaders directives.\n(CVE-2013-5704)\n\nMark Montague discovered that the mod_cache module incorrectly handled\nempty HTTP Content-Type headers. A remote attacker could use this issue to\ncause the server to stop responding, leading to a denial of service. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-3581)\n\nTeguh P. Alko discovered that the mod_proxy_fcgi module incorrectly\nhandled long response headers. A remote attacker could use this issue to\ncause the server to stop responding, leading to a denial of service. This\nissue only affected Ubuntu 14.10. (CVE-2014-3583)\n\nIt was discovered that the mod_lua module incorrectly handled different\narguments within different contexts. A remote attacker could possibly use\nthis issue to bypass intended access restrictions. This issue only affected\nUbuntu 14.10. (CVE-2014-8109)\n\nGuido Vranken discovered that the mod_lua module incorrectly handled a\nspecially crafted websocket PING in certain circumstances. A remote\nattacker could possibly use this issue to cause the server to stop\nresponding, leading to a denial of service. This issue only affected\nUbuntu 14.10. (CVE-2015-0228)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"apache2","version":"2.2.14-5ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-bin","version":"2.2.14-5ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.14-5ubuntu8.15"}],"precise":[{"name":"apache2","version":"2.2.22-1ubuntu1.8","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-bin","version":"2.2.22-1ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.8"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4","pocket":"security"}],"utopic":[{"name":"apache2","version":"2.4.10-1ubuntu1.1","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-bin","version":"2.4.10-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.10-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2013-5704","CVE-2014-3581","CVE-2014-3583","CVE-2014-8109","CVE-2015-0228"]}]},{"id":"CVE-2014-5351","published":"2014-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in\nkadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a\nresponse to a -randkey -keepold request, which allows remote authenticated\nusers to forge tickets by leveraging administrative access.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2498-1","https://www.cve.org/CVERecord?id=CVE-2014-5351"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=762479","http://krbdev.mit.edu/rt/Ticket/Display.html?id=8018"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/af0ed4df4dfae762ab5fb605f5a0c8f59cb4f6ca"]},"tags":{"krb5":["universe-binary"]},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"lucid","status":"released","description":"1.8.1+dfsg-2ubuntu0.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.10+dfsg~beta1-2ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.1+dfsg-10","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.1+dfsg-10","component":null,"pocket":"security"}]}],"notices_ids":["USN-2498-1"],"notices":[{"id":"USN-2498-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-02-10T20:04:14.117123","description":"It was discovered that Kerberos incorrectly sent old keys in response to a\n-randkey -keepold request. An authenticated remote attacker could use this\nissue to forge tickets by leveraging administrative access. This issue\nonly affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-5351)\n\nIt was discovered that the libgssapi_krb5 library incorrectly processed\nsecurity context handles. A remote attacker could use this issue to cause\na denial of service, or possibly execute arbitrary code. (CVE-2014-5352)\n\nPatrik Kis discovered that Kerberos incorrectly handled LDAP queries with\nno results. An authenticated remote attacker could use this issue to cause\nthe KDC to crash, resulting in a denial of service. (CVE-2014-5353)\n\nIt was discovered that Kerberos incorrectly handled creating database\nentries for a keyless principal when using LDAP. An authenticated remote\nattacker could use this issue to cause the KDC to crash, resulting in a\ndenial of service. (CVE-2014-5354)\n\nIt was discovered that Kerberos incorrectly handled memory when processing\nXDR data. A remote attacker could use this issue to cause kadmind to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2014-9421)\n\nIt was discovered that Kerberos incorrectly handled two-component server\nprincipals. A remote attacker could use this issue to perform impersonation\nattacks. (CVE-2014-9422)\n\nIt was discovered that the libgssrpc library leaked uninitialized bytes. A\nremote attacker could use this issue to possibly obtain sensitive\ninformation. (CVE-2014-9423)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"krb5","version":"1.8.1+dfsg-2ubuntu0.14","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"krb5-kdc","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"krb5-kdc-ldap","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"krb5-pkinit","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"krb5-user","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libgssapi-krb5-2","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libgssrpc4","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libk5crypto3","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libkadm5clnt-mit7","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libkadm5srv-mit7","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libkdb5-4","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libkrb5-3","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"},{"name":"libkrb5support0","version":"1.8.1+dfsg-2ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.14"}],"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.6","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkadm5srv-mit8","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.6"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.1","pocket":"security"}],"utopic":[{"name":"krb5","version":"1.12.1+dfsg-10ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkadm5srv-mit9","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-10ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2014-5351","CVE-2014-5352","CVE-2014-5353","CVE-2014-5354","CVE-2014-9421","CVE-2014-9422","CVE-2014-9423"]}]},{"id":"CVE-2014-3686","published":"2014-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nwpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain\nconfigurations and using wpa_cli or hostapd_cli with action scripts, allows\nremote attackers to execute arbitrary commands via a crafted frame.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2014/10/09/28","http://w1.fi/security/2014-1/","https://ubuntu.com/security/notices/USN-2383-1","https://www.cve.org/CVERecord?id=CVE-2014-3686"],"bugs":[""],"patches":{"wpasupplicant":["upstream: http://w1.fi/security/2014-1/"],"hostapd":["upstream: http://w1.fi/security/2014-1/"],"wpa":[]},"tags":{},"packages":[{"name":"hostapd","source":"https://ubuntu.com/security/cve?package=hostapd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hostapd","debian":"https://tracker.debian.org/pkg/hostapd","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"wpa","source":"https://ubuntu.com/security/cve?package=wpa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpa","debian":"https://tracker.debian.org/pkg/wpa","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.1-0ubuntu4","component":null,"pocket":"security"}]},{"name":"wpasupplicant","source":"https://ubuntu.com/security/cve?package=wpasupplicant","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpasupplicant","debian":"https://tracker.debian.org/pkg/wpasupplicant","statuses":[{"release_codename":"lucid","status":"released","description":"0.6.9-3ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.7.3-6ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2383-1"],"notices":[{"id":"USN-2383-1","title":"wpa_supplicant vulnerability","summary":"wpa_supplicant could be made to run programs if it received specially\ncrafted network traffic.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-10-14T17:30:20.787455","description":"Jouni Malinen discovered that the wpa_cli tool incorrectly sanitized\nstrings when being used with action scripts. A remote attacker could\npossibly use this issue to execute arbitrary commands.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"wpasupplicant","version":"0.6.9-3ubuntu3.2","description":"client support for WPA and WPA2","is_source":true},{"name":"wpasupplicant","version":"0.6.9-3ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpasupplicant","version_link":"https://launchpad.net/ubuntu/+source/wpasupplicant/0.6.9-3ubuntu3.2"}],"precise":[{"name":"wpasupplicant","version":"0.7.3-6ubuntu2.3","description":"client support for WPA and WPA2","is_source":true},{"name":"wpasupplicant","version":"0.7.3-6ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpasupplicant","version_link":"https://launchpad.net/ubuntu/+source/wpasupplicant/0.7.3-6ubuntu2.3"}],"trusty":[{"name":"wpa","version":"2.1-0ubuntu1.1","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"1:2.1-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.1","pocket":"security"},{"name":"wpagui","version":"2.1-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.1","pocket":"security"},{"name":"wpasupplicant","version":"2.1-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.1","pocket":"security"},{"name":"wpasupplicant-udeb","version":"2.1-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3686"]}]},{"id":"CVE-2014-7231","published":"2014-10-08T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe strutils.mask_password function in the OpenStack Oslo utility library,\nCinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not\nproperly mask passwords when logging commands, which allows local users to\nobtain passwords by reading the log.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xforce.iss.net/xforce/xfdb/96726","http://seclists.org/oss-sec/2014/q3/853","https://www.cve.org/CVERecord?id=CVE-2014-7231"],"bugs":["https://launchpad.net/bugs/1345233"],"patches":{"python-oslo.utils":["upstream: https://review.openstack.org/#/c/114614/"]},"tags":{},"packages":[{"name":"python-oslo.utils","source":"https://ubuntu.com/security/cve?package=python-oslo.utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-oslo.utils","debian":"https://tracker.debian.org/pkg/python-oslo.utils","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7203","published":"2014-10-08T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are\nunique, which allows man-in-the-middle attackers to conduct replay attacks\nvia unspecified vectors.","ubuntu_description":"\nMatthew Hawn discovered that ZeroMQ did validate that connection nonces were\nunique. A remote attacker could use this vulnerability to conduct replay\nattacks.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-7203"],"bugs":[""],"patches":{"zeromq3":[],"zeromq":[]},"tags":{},"packages":[{"name":"zeromq","source":"https://ubuntu.com/security/cve?package=zeromq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zeromq","debian":"https://tracker.debian.org/pkg/zeromq","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"zeromq3","source":"https://ubuntu.com/security/cve?package=zeromq3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zeromq3","debian":"https://tracker.debian.org/pkg/zeromq3","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.4+dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7202","published":"2014-10-08T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nstream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows\nman-in-the-middle attackers to conduct downgrade attacks via a crafted\nconnection request.","ubuntu_description":"\nMatthew Hawn discovered that ZeroMQ did not properly validate the security\nhandshake. A remote attacker could conduct a downgrade attack via a crafted\nconnection request.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-7202"],"bugs":[""],"patches":{"zeromq3":[],"zeromq":[]},"tags":{},"packages":[{"name":"zeromq","source":"https://ubuntu.com/security/cve?package=zeromq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zeromq","debian":"https://tracker.debian.org/pkg/zeromq","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"zeromq3","source":"https://ubuntu.com/security/cve?package=zeromq3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zeromq3","debian":"https://tracker.debian.org/pkg/zeromq3","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.4+dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4.0.5+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-6394","published":"2014-10-08T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nvisionmedia send before 0.8.4 for Node.js uses a partial comparison for\nverifying whether a directory is within the document root, which allows\nremote attackers to access restricted directories, as demonstrated using\n\"public-restricted\" under a \"public\" directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://nodesecurity.io/advisories/send-directory-traversal","https://www.cve.org/CVERecord?id=CVE-2014-6394"],"bugs":[""],"patches":{"node-send":[]},"tags":{},"packages":[{"name":"node-send","source":"https://ubuntu.com/security/cve?package=node-send","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-send","debian":"https://tracker.debian.org/pkg/node-send","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.4-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.9.4-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.9.4-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.9.4-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3198","published":"2014-10-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Instance::HandleInputEvent function in pdf/instance.cc in the PDFium\ncomponent in Google Chrome before 38.0.2125.101 interprets a certain -1\nvalue as an index instead of a no-visible-page error code, which allows\nremote attackers to cause a denial of service (out-of-bounds read) via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/560133004","https://crbug.com/415307","http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-3198"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"38.0.2125.111-0ubuntu0.14.04.1.1061","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0.2125.101","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"38.0.2125.111-0ubuntu0.14.10.1.1103","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3196","published":"2014-10-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nbase/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on\nWindows does not properly implement read-only restrictions on shared\nmemory, which allows attackers to bypass a sandbox protection mechanism via\nunspecified vectors.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Windows sandbox bypass"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=288152&view=revision","https://src.chromium.org/viewvc/chrome?revision=285195&view=revision","https://crbug.com/338538","http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-3196"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0.2125.101","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3193","published":"2014-10-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SessionService::GetLastSession function in\nbrowser/sessions/session_service.cc in Google Chrome before 38.0.2125.101\nallows remote attackers to cause a denial of service (use-after-free) or\npossibly have unspecified other impact via vectors that leverage \"type\nconfusion\" for callback processing.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/500143002/","https://crbug.com/399655","http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-3193"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"upstream","status":"released","description":"38.0.2125.101","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"38.0.2125.111-0ubuntu0.14.10.1.1103","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"38.0.2125.111-0ubuntu0.14.04.1.1061","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3189","published":"2014-10-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium\ncomponent in Google Chrome before 38.0.2125.101 does not properly validate\nimage-data dimensions, which allows remote attackers to cause a denial of\nservice (out-of-bounds read) or possibly have unspecified other impact via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/519873002/","https://crbug.com/398384","http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-3189"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"38.0.2125.111-0ubuntu0.14.04.1.1061","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0.2125.101","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"38.0.2125.111-0ubuntu0.14.10.1.1103","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7275","published":"2014-10-08T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not\nverify X.509 certificates from SSL servers, which allows man-in-the-middle\nattackers to spoof POP3 servers and obtain sensitive information via a\ncrafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://pyropus.ca/software/getmail/CHANGELOG","http://openwall.com/lists/oss-security/2014/10/07/33","https://www.cve.org/CVERecord?id=CVE-2014-7275"],"bugs":[""],"patches":{"getmail4":[]},"tags":{},"packages":[{"name":"getmail4","source":"https://ubuntu.com/security/cve?package=getmail4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=getmail4","debian":"https://tracker.debian.org/pkg/getmail4","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7274","published":"2014-10-08T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the\nserver hostname matches a domain name in the subject's Common Name (CN)\nfield of the X.509 certificate, which allows man-in-the-middle attackers to\nspoof IMAP servers and obtain sensitive information via a crafted\ncertificate from a recognized Certification Authority.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://pyropus.ca/software/getmail/CHANGELOG","http://openwall.com/lists/oss-security/2014/10/07/33","https://www.cve.org/CVERecord?id=CVE-2014-7274"],"bugs":[""],"patches":{"getmail4":[]},"tags":{},"packages":[{"name":"getmail4","source":"https://ubuntu.com/security/cve?package=getmail4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=getmail4","debian":"https://tracker.debian.org/pkg/getmail4","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7273","published":"2014-10-08T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not\nverify X.509 certificates from SSL servers, which allows man-in-the-middle\nattackers to spoof IMAP servers and obtain sensitive information via a\ncrafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://pyropus.ca/software/getmail/CHANGELOG","http://openwall.com/lists/oss-security/2014/10/07/33","https://www.cve.org/CVERecord?id=CVE-2014-7273"],"bugs":[""],"patches":{"getmail4":[]},"tags":{},"packages":[{"name":"getmail4","source":"https://ubuntu.com/security/cve?package=getmail4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=getmail4","debian":"https://tracker.debian.org/pkg/getmail4","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.44.0-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.46.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-7967","published":"2014-10-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as\nused in Google Chrome before 38.0.2125.101, allow attackers to cause a\ndenial of service or possibly have other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2345-1","https://www.cve.org/CVERecord?id=CVE-2014-7967"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8":[],"libv8-3.14":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"38.0.2125.111-0ubuntu0.14.04.1.1061","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0.2125.101","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"38.0.2125.111-0ubuntu0.14.10.1.1103","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"38.0.2125.111-0ubuntu1.1103","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"artful","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.2.5-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.2.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2345-1"],"notices":[{"id":"USN-2345-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-10-14T15:18:38.546844","description":"Multiple use-after-free issues were discovered in Blink. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2014-3179,\nCVE-2014-3200)\n\nIt was discovered that Chromium did not properly handle the interaction of\nIPC and V8. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2014-3188)\n\nA use-after-free was discovered in the web workers implementation in\nChromium. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to cause a denial of service\nvia applicatin crash or execute arbitrary code with the privileges of the\nuser invoking the program. (CVE-2014-3194)\n\nIt was discovered that V8 did not correctly handle Javascript heap\nallocations in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\nsteal sensitive information. (CVE-2014-3195)\n\nIt was discovered that Blink did not properly provide substitute data for\npages blocked by the XSS auditor. If a user were tricked in to opening a\nspecially crafter website, an attacker could potentially exploit this to\nsteal sensitive information. (CVE-2014-3197)\n\nIt was discovered that the wrap function for Event's in the V8 bindings\nin Blink produced an erroneous result in some circumstances. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service by stopping a worker\nprocess that was handling an Event object. (CVE-2014-3199)\n\nMultiple security issues were discovered in V8. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2014-7967)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.2.5-0ubuntu0.14.04.1","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.2.5-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.2.5-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.2.5-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.2.5-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.2.5-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.2.5-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.2.5-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.2.5-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.2.5-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.2.5-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3178","CVE-2014-3179","CVE-2014-3188","CVE-2014-3190","CVE-2014-3191","CVE-2014-3192","CVE-2014-3194","CVE-2014-3195","CVE-2014-3197","CVE-2014-3199","CVE-2014-3200","CVE-2014-7967"]}]}],"offset":64740,"limit":20,"total_results":79316}